CVE-2026-18330: Hardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4

Published Sep 3, 2026
·
Updated

A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared RSA private key to decrypt the administrator password; the weakened AES session key further reduces the effort required to compromise session confidentiality.

Successful exploitation may disclose the administrator password captured from an HTTP login session and compromise session confidentiality.

Affected Software

1 affected component
TP-Link Archer AX55=v4

Event History

Sep 3, 2026
CVE Published
via MITRE·10:24 PM
Data Sourced
via MITRE·10:24 PM
DescriptionWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

The exposed population is LAN-attached attackers who can capture an HTTP login session to the router. The issue is described specifically in the web module of TP-Link Archer AX55 v4.

2

What does an attacker need to exploit it?

An attacker needs access to the local network and a captured HTTP administrator login session. The known shared RSA-1024 private key can then be used to decrypt the captured administrator password.

3

What information could be compromised?

Successful exploitation may reveal the administrator password from the captured HTTP login session. The weakened AES session key may also reduce the effort required to compromise session confidentiality.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203